Defence Cyber Certification: the MOD has asked for Level 0 this year.
The Ministry of Defence has asked every industry partner to hold DCC Level 0 by 31 December 2026. If you supply the MOD or a prime contractor, Level 0 is the certification to start with: Cyber Essentials plus three organisational controls, assessed by an approved body and valid for three years with an annual attestation. Nerdster gets you ready, an approved certification body certifies you, and the higher levels, when a contract names one, build on the same foundation.
Defence Cyber Certification (DCC) is the Ministry of Defence's assurance scheme, delivered with IASME, that certifies defence suppliers against the controls in DEF STAN 05-138 Issue 4 at four levels, from Level 0 (fundamental controls plus Cyber Essentials) to Level 3 (defence in depth). The level is set by the Cyber Risk Profile on the contract, certification is carried out by an approved certification body and lasts three years with an annual attestation, and the MOD has asked, as a request rather than a statutory deadline, that all its industry partners hold Level 0 by 31 December 2026, with higher levels for lower supply-chain tiers scheduled after that date. Nerdster prepares you: Level 0 readiness typically £1,500 to £3,000 + VAT including Cyber Essentials, Level 1 quoted after a gap assessment, certification body fees paid separately.
- 31 Dec 2026
- The MOD's request to all industry partners to hold Level 0 by then (a request, not a statutory deadline)
- CE + 3
- Level 0 is Cyber Essentials plus three organisational controls
- 3 years
- A DCC certificate lasts three years, with an annual attestation in between
- 4 levels
- Level 0 to Level 3; the contract's Cyber Risk Profile sets which you need
Meet the requirements you will be assessed against
Level 0: basic cyber security, 3 controls plus Cyber Essentials
The floor for every defence supplier and the level the MOD has asked all industry partners to hold by 31 December 2026. It is a valid Cyber Essentials certificate covering the business-critical systems in scope, plus three organisational controls. Nerdster handles Cyber Essentials, the three controls, the evidence and the assessment preparation.
Level 1: comprehensive cyber security, 101 controls
Assigned per contract. Level 1 looks across the whole organisation, not just the IT estate: governance, risk, assets, people, suppliers and resilience. The full list of control areas is below.
Level 2: advanced cyber security, 139 controls
Assigned to higher-risk work. Level 2 adds advanced security oversight, monitoring, resilience and planning. Cyber Essentials Plus is required. We work with your team and specialist certification partners to close the gaps and prepare for assessment.
Level 3: defence in depth, 144 controls
The highest DCC level. It calls for mature cyber security capability, strong organisational resilience and a defence-in-depth approach against sophisticated, evolving threats. Cyber Essentials Plus is required.
The contract's Cyber Risk Profile decides the level
Under Cyber Security Model version 4 the Cyber Risk Profile on a contract is expressed as Level 0, 1, 2 or 3, and that is the DCC level the work needs. A certificate at a higher level satisfies every lower requirement: Level 3 covers 0, 1 and 2. If you have been given a profile, send it to us and we will explain what it means for your business.
Independent certification, prepared by us
Certification is carried out by an approved DCC Certification Body. Nerdster's role is to get you ready: assess the gaps, implement the controls, build the evidence pack and support you through the assessment.
Get your business ready for DCC. From Cyber Essentials and technical remediation to policies, evidence and assessment preparation, we help you get ready for independent certification. UK-based support, on site across the M4, M3 and A34 corridors when it helps.
Book a DCC readiness call · Not sure which level you need?
Start with Level 0: the MOD has asked for it by 31 December 2026
Level 0 is the floor. It is a valid Cyber Essentials certificate covering the business-critical systems in scope, plus three organisational controls from DEF STAN 05-138.
Where the 31 December 2026 date comes from. It is a request from the Ministry of Defence to its supply chain, not a statutory deadline and not yet a clause in every contract. On 8 May 2026 Eleanor Fairford, the MOD’s Director of Cyber Defence and Risk, wrote on the MOD’s Defence Digital blog: “I have also recently asked all industry partners to achieve Level 0 DCC certification by 31st December 2026”, adding that this “includes a requirement for obtaining Cyber Essentials for all applicable business-critical systems”, and that “where higher levels of certification are required at lower tiers in the supply chain, these should be scheduled for delivery after 31 December 2026”. Source: One year of Defence Cyber Certification, MOD Defence Digital blog, 8 May 2026.
The binding requirement on any given contract remains the Cyber Risk Profile and the Supplier Assurance Questionnaire under DEFCON 658. In practice, the December date is when MOD buyers and prime contractors will expect to see a Level 0 certificate. If you supply the MOD or a prime and hold nothing yet, Level 0 is the place to begin, whatever level your next contract eventually names.
What Level 0 asks of you, in plain terms:
- Cyber Essentials, current and covering the systems the defence work touches
- The three Level 0 controls from the standard, in place and evidenced
- An assessment by an approved DCC certification body, then an annual attestation and re-certification every three years
Level 0 readiness with Nerdster includes:
- Cyber Essentials review or readiness and certification, depending on where you are
- A technical gap check against the Level 0 controls, with fixes carried out where you want us to
- The DCC Level 0 readiness review and a short evidence pack organised the way the certification body expects
- Coordination with your chosen approved DCC certification body and support through the assessment
What it costs
Four things are priced separately, and we put all four in one written quote so there are no surprises. The ranges below are indicative, drawn from published certification body prices in September 2026; the body you choose sets its own fee.
| What | Who charges | Indicative range |
|---|---|---|
| Cyber Essentials (the prerequisite for every level) | Nerdster, including the certification fee | From £795 + VAT for a certification review, from £1,495 + VAT for readiness and certification, Plus from £2,995 + VAT |
| DCC readiness: gap assessment, policies, evidence pack, assessment preparation | Nerdster | Level 0 typically £1,500 to £3,000 + VAT including Cyber Essentials readiness. Level 1 quoted after the gap assessment, so you pay for the gaps you actually have |
| Technical remediation: MFA, patching, device replacement, licences | Nerdster, quoted per fix | Depends entirely on what the gap assessment finds |
| Independent assessment and certificate | The DCC certification body, paid to them | Level 0: one body’s published 2026 list runs from £650 + VAT (1 to 9 staff) to £1,000 + VAT (250+ staff) for a three-year certificate. Level 1 and above: set by the body per organisation and considerably higher; we confirm the figure with your chosen body before quoting |
| Ongoing support (optional) | Nerdster managed service | Quoted monthly; keeps the controls maintained for the annual attestation and the next renewal |
Level 1 and above
Level 1 is where most SME suppliers first feel the difference. Its 101 controls look across the whole organisation, not just the IT estate, and cover:
- Security governance
- Policies and procedures
- Risk management
- Asset management
- User and access controls
- Endpoint security
- Patch management
- Encryption
- Email and network security
- Staff awareness
- Supplier security
- Vulnerability management
- Logging and monitoring
- Incident response
- Business continuity and recovery
Levels 2 and 3 are reserved for high and substantial risk programmes. Both require Cyber Essentials Plus, and both call for more advanced monitoring, resilience and planning. For those levels we work with your internal team and specialist certification partners to identify gaps, implement controls and prepare the organisation for assessment.
DEF STAN 05-138 and DCC: the difference
DEF STAN 05-138 Issue 4, published in May 2024, is the Ministry of Defence’s cyber security standard for its supply chain. It defines the controls for each Cyber Risk Profile: 3 at Level 0, 101 at Level 1, 139 at Level 2 and 144 at Level 3. It is the list of things you must do.
Defence Cyber Certification is the independent certification, run by IASME for the MOD, that proves you do them. Certification is carried out by an approved DCC certification body; Nerdster is not one, which is why our advice is not tied to your assessment result.
Two practical consequences:
- If a tender, contract or prime contractor requirement quotes “DEF STAN 05-138” rather than “DCC”, it is the same set of controls, and DCC certification is the recognised way to evidence them. MOD Industry Security Notice 2026/02 confirms that a valid DCC certificate at or above the level a contract requires is accepted as evidence of the DEF STAN 05-138 controls for that contract, and that a higher certificate satisfies every lower level.
- The Supplier Assurance Questionnaire, completed through the MOD’s Supplier Cyber Protection Service, still has to be submitted. DCC evidences the controls; it does not yet replace the questionnaire.
Not sure which level you need?
You do not need to decode the Defence Standard yourself. For a plain-English walk through the scheme, the MOD’s request and the kinds of business it reaches, read Defence Cyber Certification: who needs it and why.
If an MOD customer, prime contractor or procurement process has given you a Cyber Risk Profile, we review the requirement and explain what it means for your business. If you are preparing ahead of a defence opportunity, we assess your current environment against the appropriate DCC requirements.
From requirement to ready
1. Understand
We review your DCC requirement, Cyber Risk Profile and current cyber security environment. You get a clear explanation of what applies to your organisation.
2. Assess
We compare your existing security against the required controls. Already have Cyber Essentials, ISO 27001, Microsoft 365, Intune or other controls in place? We identify what can be reused and where the real gaps are.
3. Fix
We help implement what is missing. That can include policies and procedures, Microsoft 365 security, Intune and endpoint management, MFA and identity security, access controls, device configuration, patch management, EDR and malware protection, firewalls and network security, encryption, backups and recovery, logging and monitoring, and incident response.
4. Evidence
Having security controls is not enough if you cannot demonstrate them. We build an organised evidence pack showing how each control is implemented and managed.
5. Prepare
Before independent assessment, we work through outstanding issues and help your team prepare for the certification process.
6. Maintain
Cyber compliance is not a once-a-year scramble. Nerdster can continue managing your IT, cyber security, monitoring, policies and evidence so your environment stays ready for the annual attestation.
Already have Cyber Essentials?
Good. You already hold part of the foundation, and at Level 0 most of it. Above that, DCC asks about how the whole business runs its security: who owns risk, how suppliers are vetted, what happens when something goes wrong. Nerdster helps bridge that gap.
- Cyber Essentials. Basic technical cyber hygiene. See our Cyber Essentials packages.
- DCC readiness. Technology, people, processes, policies, evidence and resilience.
- Independent DCC assessment. Assessment and certification through an approved DCC certification body licensed by IASME.
What you get
- DCC gap assessment. A structured review against the controls applicable to your required DCC level.
- Readiness score. Where you are today, what is already covered and what still needs attention.
- Remediation plan. A prioritised action plan instead of a 100-page compliance document nobody understands.
- Technical implementation. Where required, Nerdster implements and manages the underlying security technology.
- Policies and procedures. The governance and operating procedures the controls call for.
- Evidence pack. Evidence organised against the relevant controls, ready for assessment preparation.
- Certification support. We work alongside your chosen independent DCC certification body through the certification process.
- Ongoing management. Your security controls kept maintained after certification.
Already using Microsoft 365?
You may be closer than you think. For many SMEs, capabilities already available within Microsoft 365, Entra and Intune contribute to identity, MFA, device management, access control, security configuration, endpoint protection, logging and data protection.
The challenge is configuring them correctly, documenting them and filling the gaps around them. That is where Nerdster comes in. See our Microsoft 365 support.
Renewal and ongoing obligations
Certification is not the end of it. Plan for these from the start:
- DCC certificates last three years, with an annual attestation in between to confirm the controls are still in place.
- The Supplier Assurance Questionnaire is reviewed annually on the contract anniversary under DEFCON 658, and the Cyber Risk Profile can be reset at that point, which can change the level you need.
- Cyber Essentials renews every 12 months and must stay valid throughout. Levels 2 and 3 need a valid Cyber Essentials Plus for the whole certification period.
- New and renewed MOD contracts carry the requirement. Cyber Security Model version 4 went live in October 2025 and has applied to new risk assessments and questionnaires since 3 December 2025, so a renewal is where most suppliers first meet it.
Nerdster’s optional managed service keeps the controls maintained so each of these is routine rather than a project.
Official sources
- MOD guidance: Cyber Security Model on GOV.UK, including the Supplier Assurance Questionnaire process.
- Industry Security Notice 2025/07: implementation of Cyber Security Model version 4 from 3 December 2025 and the annual questionnaire review.
- Industry Security Notice 2026/02: use of DCC as assurance of the DEF STAN 05-138 controls under DEFCON 658.
- The 31 December 2026 date: One year of Defence Cyber Certification, MOD Defence Digital blog, including the request that industry partners reach Level 0 by 31 December 2026.
- IASME: launch of the Defence Cyber Certification scheme, the scheme owner and certification authority.
Built for SMEs in the defence supply chain
You should not need a full-time compliance department just to understand what your MOD customer is asking for. Nerdster combines IT, cyber security and practical compliance implementation into one service, and focuses on getting the controls working in the real business, not on producing policies for a folder.
- We implement the changes ourselves rather than handing you a list of what is wrong.
- You always know what is complete, what is missing and what happens next.
- If you want, we keep running the underlying security controls after the project finishes.
- Support comes from a UK technology and cyber security team.
Do not wait for a defence opportunity to expose the gaps
Whether you have already been given a DCC requirement or simply want to become ready to supply the defence sector, we will show you where you stand and what needs to happen next. Start with a DCC readiness review: understand your current position, identify the gaps and build a clear route to certification.
Last updated:
FAQ
Frequently asked questions
Do I need DCC to work with the MOD?
It depends on the contract and the Cyber Risk Profile assigned through the MOD Cyber Security Model. Separately, the MOD has asked its industry partners to hold Level 0 by 31 December 2026: a request made by its Director of Cyber Defence and Risk on 8 May 2026 (linked under Official sources below), not a statutory deadline. Higher levels are set per contract. If DCC or Defence Standard 05-138 appears in a tender, contract or prime-contractor requirement, send it to us and we will explain what is required.
What is DEF STAN 05-138?
DEF STAN 05-138 Issue 4 is the Ministry of Defence's cyber security standard for its supply chain, and the formal name behind Defence Cyber Certification. DCC is the independent certification against it; the level you need is set by the Cyber Risk Profile of the work.
Is DCC the same as Cyber Essentials?
No. Cyber Essentials is part of the foundation, but DCC covers a much wider set of organisational cyber security requirements. All DCC levels build on Cyber Essentials, and Levels 2 and 3 require Cyber Essentials Plus.
Can Nerdster certify us?
No. Independent DCC certification is carried out by an approved DCC Certification Body. Nerdster's role is to make you ready: assess the gaps, implement the controls, prepare the evidence and support you through the certification process.
We already have ISO 27001. Do we need to start again?
Not necessarily. DCC shares control areas with ISO 27001, NIST and Cyber Essentials. We identify the controls and evidence you already hold that can be reused before recommending any additional work.
We do not have an internal IT or cyber team. Is that a problem?
No. Nerdster can implement and manage the technology and security controls as your outsourced IT and cyber security partner, and keep them maintained after certification.
How long does DCC certification last, and what happens each year?
A DCC certificate is valid for three years, with an annual attestation in between to confirm the controls are still in place. Separately, DEFCON 658 requires the Supplier Assurance Questionnaire to be reviewed annually on the contract anniversary, when the Cyber Risk Profile can be reset. Cyber Essentials, which every level depends on, renews every 12 months, and Levels 2 and 3 need a valid Cyber Essentials Plus throughout.
What does DCC cost?
Four things are priced separately: Cyber Essentials (from £795 + VAT with Nerdster), Nerdster's readiness work (Level 0 typically £1,500 to £3,000 + VAT including Cyber Essentials readiness; Level 1 quoted after the gap assessment), any technical remediation (quoted per fix), and the certification body's own assessment fee (one body's published 2026 list runs from £650 + VAT for a micro business to £1,000 + VAT for a large one at Level 0; Level 1 fees are set per organisation and are considerably higher, and we confirm them with your chosen body before quoting). We put the whole picture in one written quote before work begins.
Is DCC the same as DEF STAN 05-138?
No. DEF STAN 05-138 Issue 4 is the standard: the list of controls for each Cyber Risk Profile. DCC is the independent certification that proves you meet them. MOD Industry Security Notice 2026/02 confirms that a valid DCC certificate at or above the level a contract requires is accepted as evidence of the DEF STAN 05-138 controls for that contract, although the Supplier Assurance Questionnaire itself still has to be completed.
Tell us about your DCC requirement
Tell us the level you have been asked for, where you are with Cyber Essentials and the date you are working to. We reply within one working day with the likely level, what getting ready involves and an indicative price.
Message sent
Thanks for getting in touch. We will reply within 2 hours on a business day.
Contact details
0330 043 7414
Mon-Fri 8am-6pm
hello@nerdster.co.uk
We reply within 2 hours
71-75 Shelton Street
Covent Garden, London WC2H 9JQ
IT assessment
A review of your IT, your security posture and your compliance readiness, free of charge.
- 30-minute consultation call
- Infrastructure & security review
- Compliance gap analysis
- Custom recommendations report
Related compliance services
Find out where you stand today
Book a compliance review. We assess your readiness against the current requirements and give you a priority order for closing the gaps.
- No callout fees
- No-obligation assessment